Skip to content
Web Development

Ecommerce Security: How to Protect Your Store, Customers and Payments

Ecommerce security in layers: staff accounts, customer accounts, payments and scripts, platform and apps, data protection, monitoring, incident response and testing.

Quick answer

Secure an online store in layers. Protect accounts with multi-factor authentication and least-privilege access for staff, and bot and takeover protection for customers. Keep card data off your systems with hosted checkout or tokenization, and control scripts on payment pages. Maintain the platform: patch, review apps and their permissions, manage secrets and set security headers. Back up, monitor, prepare an incident response plan and get professional security testing for custom code. This article is general guidance, not a security assessment.

The Ecommerce Threat Picture

Online stores hold what attackers want: payment flows, customer personal data, accounts with stored value (loyalty points, gift cards) and inventory that can be resold. Common incidents include compromised staff or admin accounts, customer account takeover through reused passwords, malicious scripts injected into checkout or product pages, vulnerable or over-permissioned apps and plugins, misconfigured storage exposing data, and fraud such as card testing.

This article explains defensive controls at a strategic level. It doesn't describe attack techniques, and it isn't a substitute for professional testing. For general website security, see website security checklist and secure website development.

RiskTypical impactPrimary defences
Staff account compromiseFull store control, data accessMFA, least privilege, access reviews
Customer account takeoverFraud, loyalty theft, data exposureBot protection, rate limits, MFA options, breach detection
Malicious scripts on payment pagesCard and personal data theftHosted payment pages, script inventory, integrity monitoring
Vulnerable or excessive apps and pluginsData access, site compromiseApp review, minimal scopes, updates
MisconfigurationData exposureSecure defaults, configuration reviews
Card testing and payment fraudChargebacks, feesFraud tools, velocity limits, bot protection

Layer 1: Staff and Admin Accounts

Most store compromises start with an account. Enforce multi-factor authentication for every staff account on the ecommerce platform and on connected systems: email, domain registrar, DNS, hosting, code repositories, payment provider and analytics. Give each person their own account with only the permissions they need, remove access promptly when people leave or agencies finish work, and review access regularly. Broken access control has ranked first in the OWASP Top 10 web application risks (OWASP Top 10), and many real incidents come from over-privileged or forgotten accounts.

  • MFA on platform, email, domain, DNS, hosting, repositories, payments
  • Individual accounts, no shared logins
  • Role-based permissions; admin rights limited
  • Collaborator and agency access time-limited and reviewed
  • Quarterly access review with owners
  • Offboarding checklist that removes all access

Layer 2: Customer Accounts

Customer accounts are targeted with credentials leaked from other sites. Defences include bot protection and rate limiting on login and account creation, detection of unusual login patterns, optional or risk-based MFA or passwordless login, notification of account changes (email, address, password) and protection of stored value such as loyalty points and gift card balances. Balance security with accessibility: avoid puzzle CAPTCHAs that block disabled users, and allow password managers. See ecommerce accessibility.

Layer 3: Payments and Scripts

The safest approach is to keep card data off your systems entirely: use a hosted checkout or payment fields provided by your payment provider, and tokenization for stored payment methods. This reduces your PCI DSS scope but doesn't remove responsibility. PCI DSS v4.0.1 is the current version, and requirements that became mandatory on 31 March 2025 include managing scripts on payment pages and detecting unauthorized changes. The PCI Security Standards Council has clarified how these apply to merchants using embedded payment pages under SAQ A (PCI Security Standards Council). Confirm your obligations with your payment provider or a qualified assessor.

Beyond compliance, control scripts across the store: keep an inventory of third-party scripts, remove unused ones, load them only where needed, use a content security policy where practical, and monitor for unexpected changes.

Unsure how exposed your store is?

ZSpace reviews ecommerce setups, apps, scripts and integrations and helps prepare for professional security testing.

Start a Project

Layer 4: Platform, Apps and Code

On hosted platforms, focus on what you control: apps, themes, integrations and settings. Install only necessary apps from reputable developers, review the data access they request, and remove unused ones. On self-hosted or custom platforms, patch the platform, plugins and dependencies promptly, run dependency scanning, and follow secure development practices. Keep secrets (API keys, tokens) out of code and front-end bundles, store them in a secrets manager or environment configuration, rotate them, and give each integration its own limited credentials.

AreaHosted platform (e.g. Shopify)Self-hosted / custom
Infrastructure and patchingPlatformYou
Checkout securityPlatform (hosted checkout)You or payment provider
Apps and pluginsYou choose and reviewYou choose, patch and review
Theme / frontend codeYouYou
Integrations and APIsYouYou
Staff accessYouYou

Layer 5: Data Protection

Collect only the customer data you need, restrict access to it, encrypt it in transit (HTTPS everywhere) and at rest where you control storage, and set retention periods. Be careful with exports: order and customer exports in spreadsheets, shared drives or email are a common source of leaks. Security and privacy overlap here. See ecommerce privacy and customer data.

Layer 6: Fraud and Bots

Fraud tools provided by payment providers and platforms score orders for risk. Configure them, review flagged orders and use velocity limits to reduce card testing. Bot management helps with credential stuffing, scraping, inventory hoarding during launches and fake account creation. Monitor chargeback rates, which card networks and payment providers track.

Layer 7: Monitoring, Backups and Incident Response

Monitor for signs of trouble: unexpected admin logins, new apps or staff accounts, changes to themes or scripts, spikes in failed logins or declined payments, and unusual data exports. Keep backups of data and code you control and test restoring them. Write an incident response plan covering roles, contacts (platform support, payment provider, legal advisers), containment, evidence preservation, notification (duties vary by jurisdiction) and recovery. Practise it.

  • Alerts for new admins, apps and theme changes
  • Login and payment anomaly monitoring
  • Tested backups for data and code you control
  • Incident response plan with named roles and contacts
  • Legal advice identified for breach notification
  • Post-incident review process

Security for AI Features

AI assistants, agents and integrations add new risks: prompt injection, over-permissioned tools, leakage of customer data to model providers and actions taken on manipulated inputs. Apply the same principles: least privilege, validation, logging, human approval for high-impact actions and data minimization. See AI agents for ecommerce.

Professional Testing

Guidance and checklists help you get basics right; they don't find everything. Custom code, headless storefronts, integrations and larger stores warrant professional security testing by qualified specialists, with appropriate authorization and scope. Use an internal review to prepare for that testing and to fix obvious gaps first. See ecommerce security audit.

Security for Headless and Custom Builds

Headless storefronts and custom integrations move more responsibility to your team. API tokens must be scoped correctly (public storefront tokens vs private server tokens), secrets must stay server-side, server routes need input validation and rate limiting, and hosting needs secure configuration. Dependencies must be kept up to date. These builds warrant professional security testing before launch and after major changes. See Hydrogen vs traditional Shopify.

  • Public and private API tokens used in the right places
  • No secrets in client bundles or public repositories
  • Input validation and rate limiting on server routes
  • Dependency updates and scanning
  • Secure hosting configuration and headers
  • Professional testing before launch

Security Responsibilities Across Teams

Security fails when everyone assumes someone else owns it. Assign clear responsibilities: platform and access to an operations or ecommerce lead, code and integrations to engineering, scripts and tags to marketing with engineering review, vendor review to whoever approves apps, and incident response to a named lead with backup. Review responsibilities when teams or agencies change.

AreaTypical owner
Staff accounts and permissionsEcommerce or operations lead
Apps and vendorsEcommerce lead with engineering review
Theme and custom codeEngineering or agency
Tags and scriptsMarketing with engineering approval
Payments and fraudFinance or operations
Incident responseNamed lead and deputy

Training Staff

Many compromises start with phishing or social engineering aimed at staff: fake platform notices, requests to add a collaborator, changes to payout details. Train staff to verify unusual requests through a separate channel, report suspicious messages, and never share MFA codes. Keep training short and repeated, and include agencies and contractors with admin access.

Common Mistakes

  • No MFA on email, domain or payment accounts
  • Shared admin logins
  • Old agency and app access never removed
  • Unreviewed third-party scripts on checkout-adjacent pages
  • Secrets in front-end code or repositories
  • Customer exports left in shared folders
  • Assuming the platform handles everything

Ready to strengthen your store's security?

Talk to ZSpace about secure ecommerce development, Shopify app and access reviews and security monitoring automation.

Start a Project

Conclusion

Ecommerce security is layered: protect accounts, keep card data off your systems and control scripts, maintain apps and code, minimize data, fight fraud and bots, monitor and prepare for incidents, and use professional testing for what checklists can't cover. Related: ecommerce compliance and mobile app security.

FAQ

Common questions

Compromised staff accounts, account takeover of customer accounts, malicious or vulnerable third-party scripts and apps (including payment page skimming), misconfiguration, unpatched software, exposed secrets, fraud and bots, and data leaks.

Get in touch

Have a project in mind?

Whether you're building a new digital product, improving an existing website, or looking to automate part of your business — let's talk.